Loading video...

Video Failed to Load

Go Home

Bypass the uploader and upload any file the attacker wants just by using the null byte %0d%0a Bypass technique used : shell.php%0d%0a.jpg Tip: Always test all null bytes #bugbountytips #bugbounty #CyberSecurity #Developers #RedTeaming #bug #Security

0 Comments

No comments available

Comments from the original post will appear here

Related Videos

How do you create your payloads in 2025? At MSec Operations we prefer to use DLL sideloading for EDR evasion. This technique allows our malicious code to run within a signed, legitimate executable. Combining this technique with other useful techniques will provide stable execution to fly under the radar. 🛸 The following video demonstrates the use of #RustPack to create such a payload in just a few seconds. The command line usage shows that our input payload is a simple unmodified Apollo C2 executable. We want to clone all the exported functions from the original Windows wininet.dll to create our own library with the same name. The execution of the payload will be delayed by ~5 seconds in this case, without using the Win32 sleep function, but by performing random calculations. ⏲️ Hardware breakpoints are used to bypass the Antimalware Scan Interface (AMSI). Without an AMSI bypass, Apollo would be flagged as a C# assembly when loaded. 🎓 Our payload will only fire on a domain joined system, this basically prevents it from running in e.g. sandbox environments. 🤠 Last but not least, in this example, the encrypted payload itself is stored in a separate file on the target system and not even in the same folder as our malicious DLL. Anyone analysing just the DLL will never be able to find out what the payload is. Automatic sample submissions for cloud analysis usually only upload the executable or DLL, emulators won't see the real payload either. 🤠 Tired of creating such payloads yourself? With #RustPack it's really easy, and payloads always look completely different, even if the same payload is packed twice to avoid signature-based detection Contact us via info[at] for more information! 👍

MSec Operations

26,003 views • 1 year ago

Ok, I tried the responsible disclosure route, but since the maintainers have been completely unresponsive both over email and here on X, here goes Auth bypass -> RCE on the "AgentOS" with "16 security systems", OpenFang by RightNow (YC F26) Oh and those security systems? Turns out they weren't even doing what they were supposed to do The "taint tracking" used to enforce an allowlist of commands for agents could be trivially bypassed in at least four different ways (command-splitting on |, ;, && and || but a whitelisted command followed by & cmd, `cmd`, $(cmd) and cmd works fine. Overall, they're fighting a losing game by implementing a command line parsing based sandbox rather than using an actual sandbox (using seccomp-bpf, for instance), a container or a microVM As for the AES-256-GCM based auth in the OpenFang P2P protocol, well, besides being vulnerable to a replay attack, the protocol itself is completely in plaintext after the handshake! Regarding the "WASM sandboxes", turns out they aren't actually used for anything, there's not a single WASM agent in the repo, and since rather than conforming to WASI they require implementing a completely custom API, it's unlikely that anyone would bother making a WASM based agent in the first place (not even the maintainers do, so) And as for the "Merkle audit trail", that audit trail is stored entirely in-memory, so simply restarting the daemon is enough to erase any traces of that trail Anyway, enjoy the RCE PoC!

Joel Eriksson

12,327 views • 4 months ago

The Halderman Report proved that votes can be ALTERED on Dominion machines, revealing critical flaws and features that let insiders flip votes either on-site or remotely, even subverting paper trails. Dominion voting machines, specifically the ImageCast X and ICX ballot-marking devices, have severe, exploitable security flaws that allow votes to be altered. All used in the 2020 election and others. Malicious actors, corrupt insiders, including hackers with physical access, corrupt election officials, or remote attackers via election management systems, can change election results without detection. These vulnerabilities undermine the entire election process, subvert audit trails and paper records, and prove the machines cannot be trusted. The flaws pose an ongoing threat to U.S. elections with obvious strong implication tied to the stolen 2020 election. Arbitrary code execution is extremely vulnerable allowing an attacker to install malicious software on the machines. This can be done with temporary physical access, even by a voter at a polling place, or remotely by compromising the central election management system, the EMS, then spreading malware to every ballot-marking device in a jurisdiction. If one computer or machine is attacked or compromised, then ALL of the machines on the network are compromised. There is a vast variety of vote alterations capable. Malware can modify the QR codes on the paper ballots printed by the machines, effectively changing the recorded votes while the paper trail appears normal to voters and auditors. Multiple severe security flaws discovered across nearly every part of the exposed system, including how election definitions are loaded. Proof-of-concept attacks were demonstrated by Halderman and his team showing it was possible to secretly alter votes on test machines. These attacks can bypass procedural protections practiced by states, logic & accuracy testing, chain-of-custody, etc. The report concludes that the vulnerabilities are serious enough to allow large-scale vote manipulation in our elections and most likely already have before and post 2020 election.

The SCIF

19,397 views • 26 days ago

Is reverse proxy phishing slowly dying? 💀🎣 This is what I've been trying to find out during the past several months. Major websites have caught up and vastly improved their security, successfully detecting malicious traffic originating from reverse-proxy phishing servers. The attackers have changed their tactics and begun utilising a new method that involves using a real web browser to sign in on the phished user's behalf. In the video I've just released, I am demonstrating a live demo of a modern phishing attack using the Credential Relay Phishing technique, which evades all current anti-phishing measures deployed against reverse-proxy phishing. To simulate a phishing attack against a Google account secured with FIDO MFA, I am using the latest features of Evilginx Pro to downgrade the FIDO MFA to less secure & phishable MFA alternatives. Additionally, the attack simulation employs a Browser-in-the-Browser social engineering technique to spoof the phishing URL in the address bar of the fake pop-up window, displaying the sign-in page. Everything you see in the video is ready to use in the latest beta version of Evilginx Pro, available exclusively to vetted cybersecurity professionals working within cybersecurity companies or internal red teams. Evilginx Pro's latest features include: Phishlets 2.0: A complete rewrite of the old phishlets format now allows for modification of every part of HTTP traffic going through the reverse proxy server. The new format allows hosting of static website content utilising external modules such as Evilpuppet to simulate Credential Relay Phishing attacks. Downgrading FIDO MFA: With the most recent implementation of Evilpuppet, it is now possible to control a separate background browser session and sign in on behalf of the phished user, allowing the attacker to be the one responsible for choosing which MFA method the user should authenticate with. Browser-in-the-Browser: It is now possible to embed any phishing page within a fake browser pop-up window, rendered with JavaScript and stylised for the OS on which the page is displayed. This enables the construction of extremely convincing social engineering attacks, as the URL in the pop-up window can be spoofed to any value using legitimate hostnames. If you want to use these features in your next red team engagement or assess your company's readiness against modern phishing attacks, make sure to give Evilginx Pro a try. Hope you enjoy the video! 💗 Happy phishing! 🪝🐟 Kuba

Kuba Gretzky

24,158 views • 4 days ago

🚨 THREAT INTELLIGENCE ALERT 🚨 The tool 🇨🇳 KernelGhost820 is being actively sold on the underground market for US$ 2,500, complete with full source code. This is a professional-grade suite with an intuitive graphical interface and six advanced modules, specifically designed for EDR evasion and sophisticated ransomware operations with efficient lateral movement: • EDR Removal Engine: Automatically detects and terminates more than 40 security products (including CrowdStrike, SentinelOne, Microsoft Defender, Kaspersky, and others). Supports Kernel, UserMode, and NTDLL termination modes, kernel driver loading for protected processes, disabling Windows Defender, and blocking telemetry connections. • Ransomware Module: Dual encryption using AES256CBC + RSA2048, supporting over 70 file types (documents, images, databases, backups, etc.). Automatically deletes Volume Shadow Copies to prevent recovery, generates custom ransom notes with Bitcoin addresses and contact emails, and changes the desktop wallpaper. • Remote Operations & Mass Deployment: Connects to remote devices on the local network via WMI (requires username and password). Scans installed software on target hosts, performs process termination, and enables one-click full tool deployment. Includes full-network scanning for open SMB port 445 with real-time progress tracking. • Detailed Process Manager and full Operation Logger (exportable to TXT). This tool significantly lowers the technical barrier for advanced ransomware actors targeting corporate environments. Immediate monitoring recommendations: • Evaluate the resilience of your EDR/XDR controls against kernel-mode bypass techniques • Intensify monitoring of anomalous SMB (port 445) traffic and WMI connections • Strengthen network segmentation and the principle of least privilege Our team is actively tracking this tool and any emerging variants. #ThreatIntelligence #Ransomware #EDRBypass #CyberSecurity #InfoSec #CyberThreat

Clandestine

40,619 views • 2 months ago

Hi everyone, At CoinDCX : India Ka Crypto Coach, we have always believed in being transparent with our community, hence I am sharing this with you directly. Today, one of our internal operational accounts - used only for liquidity provisioning on a partner exchange - was compromised due to a sophisticated server breach. I confirm that the CoinDCX wallets used to store customer assets are not impacted and are completely safe. Before I share further details on this, I would like to highlight that: -No customer funds have been impacted -Your assets remain completely safe and protected in our secure cold wallet infrastructure -All trading activity and INR withdrawals are fully operational The incident was quickly contained by isolating the affected operational account. Since our operational accounts are segregated from customer wallets, the exposure is only limited to this specific account and is being fully absorbed by us - from our own treasury reserves. Our internal security and operations teams have been working through the day along with leading cybersecurity partners to investigate the matter, patch any vulnerabilities and trace the movement of funds. We are collaborating with the exchange partner to block and recover assets, including coming out with a bug bounty program soon. Every security incident is a learning and we will learn from this and further strengthen our platform, more importantly this is our time to win this war against cyberthreats in the industry and we commit to work together with experts to secure our industry. I understand incidents like this can be unsettling - even when customer assets are unaffected. That's why I am sharing this incident with you with full transparency. Thank you for your continued trust. I will keep you informed on a real time basis as we learn more. 🙏

Sumit Gupta (CoinDCX)

718,341 views • 1 year ago

🇮🇷 Changing Iran's nuclear doctrine in the event of an attack on peaceful nuclear centers 🇮🇷 The Commander of the Security and Safety Corps of the country's nuclear centers said: "The country's nuclear centers are completely safe. The threat of the Zionist regime to Iran's nuclear centers makes it possible to revise and deviate from the declared nuclear policy and considerations." 🇮🇷 Emphasizing the complete security of the country's nuclear centers in response to the threat of the Zionist regime to attack these centers, General Ahmad Haq-Talab said: “A revision of the doctrine and nuclear policy of the Islamic Republic of Iran and a deviation from the previously announced declaration is possible and is being discussed.” 🇮🇷 According to public relations information for the entire IRGC, the Commander of the Nuclear Defense and Security Corps, Brigadier General Ahmad Haq-Talab, said in a conversation about the possible actions of the Zionist regime in response to the victorious Operation True Promise to attack the country's nuclear facilities: “These threats do not apply either to today or to yesterday, since in previous years the false Zionist regime, in addition to threats, undertook sabotage and terrorist actions in the country’s nuclear industry.” 🇮🇷 He added: “Although all countries are prohibited from attacking nuclear facilities in accordance with international protocols and standards, as well as the rules and regulations of the International Nuclear Agency, the Islamic Republic of Iran has always been ready to counter these threats from the very beginning.” General Haq-Talab, noting that the Zionist regime recently violated all international laws and regulations by committing a criminal act by attacking the consular section of the Embassy of the Islamic Republic of Iran in Syria, stated: “By the grace of God, thanks to the measures of the Supreme Leader and Commander-in-Chief, as well as the efforts of the children of the Iranian nation in the armed forces, using passive defense plans, as well as the most modern means and equipment, as well as thanks to the dispersal of our country’s nuclear facilities and complexes over the vast territory of Iran, We can deal with any threat from the Zionist regime." 🇮🇷 The commander of the security and safety corps of the country's nuclear centers, emphasizing that the armed forces of the Islamic Republic of Iran are in full readiness, noted: "The nuclear centers of the Zionist enemy have been identified and the necessary information about all targets is at our disposal, so to speak, to respond to possible actions. They hold the trigger in their hands to launch powerful missiles to destroy the specified targets." 🇮🇷 He said: “If the Zionist regime wants to take action against our nuclear facilities and centers, it will definitely face our reaction and the regime’s nuclear facilities will be attacked using advanced weapons.” 🇮🇷 He further emphasized: “If the fake Zionist regime wants to use the threat of an attack on our country’s nuclear centers as a tool of pressure on Iran, then a revision of the nuclear doctrine and policy of the Islamic Republic of Iran and a retreat from the previous declaration are possible and discussed.” 🇮🇷 General Haq-Talab, emphasizing that the order of the Supreme Leader must be carried out today without delay, said: “If the Zionist regime commits an act of aggression against Iran, the type of response will be planned by the armed forces of the Islamic Republic of Iran, and they must be confident that the blow they receive from the armed forces will be remembered in history, like Operation True Promise.” ."

𝕊𝕡𝕣𝕚𝕟𝕥𝕖𝕣 𝕻𝕣𝕖𝕤𝕤

37,377 views • 2 years ago

The $AEGIS DApp portal is now open to all: 🛡️ At Aegis, we believe in empowering the blockchain full of security, transparency and innovation. The Aegis Dapp has been under development for several months prior to the launch of $AEGIS and with that we have been able to build what we believe has the potential to change how users go about their day to day security. We are thrilled to share our progress and truly exciting news with you all. 🎯 First things first, at Aegis, we want to make it clear that the value of what we seek to bring to security across the blockchain, comes from our big vision, our strong team, and our commitment to long-term goals. ℹ️ Let’s kick this off with some information that is constantly happening, which is behind the scenes. Our full team is dedicated to the opportunity that lays ahead of us with becoming the leading voice/name for security, grasping every aspect with innovation, hard work, passion and commitment to see this sector grow. Everyone is aware of how important security is, a heartwarming mention to Messari for including us on how they see this sector growing rapidly and pushing a 10 Billion evaluation. We take that recognition with full responsibility and gratitude as we've been working hard on some really powerful stuff that could change the game for our industry. If you read the title and report itself, I’m sure that’ll give you some insight to what’s coming, and to the vast extent of what you can expect Aegis to be working towards. —> 🤝 This comes from teaming up with others within this sector and coming up with new tech to projects driven by our community, within the pipeline you can be confident that what we are building will push the cryptocurrency industry as a whole into a better future, the magnitude to what Aegis brings will not stop until we can confidently say, “Negative security reports across the blockchain are at an all time low, thousands of users are satisfied that Aegis is protecting them and their assets.” We're sticking to our vision no matter what the market does or whatever else comes our way. We plan to build what we set out to and we will see to it that our ecosystem is met. We've been working on some pretty amazing products that will be available within our Dapp, let’s go over what we offer: * AI Audits * Live Monitoring * Penetration Testing * Bug Bounties * Live Watchdog * Token analytics for everyday users, developers, teams, auditors, institutions, investors. ⬇️ Let’s break it down for you in some simple steps: AI AUDITS: We have trained our LLM models as AI AGENTS, these consist of 3 people ( AI AGENTS ) for the audits that are performed. - Audit - Reviewer - Judge Each one analyzes with a different personality, let’s check what personalities our AI AGENTS consist of: 3 different perspective auditors. 1 - Fine-tuned model x amount reads the code and generates the audit. ✅ 2 - Model x amount reviews the code and fact checks thoroughly. ✅ 3 - Model x amount ranks the code based on the severity outcome. ✅ ⌚️ Live Monitoring/Watchdog: The Live Monitoring/Watchdog system is designed to provide real-time surveillance of smart contracts, ensuring the detection and prevention of any potentially harmful transactions or malicious activities. Through the utilization of an AI Agent model, the system is trained to proactively identify and thwart suspicious behavior, thereby safeguarding the integrity of the smart contracts. Also, a paid sophisticated threat detection model is available for more intricate protocols and Dapps, offering an advanced level of protection against potential threats. This proactive approach is crucial in mitigating the risk of exploitation and ensuring the security of the smart contract ecosystem. 🖊️ Pen Testing: Our platform offers Pen Testing services to developers, providing a controlled environment for whitehat hackers to simulate attacks and identify vulnerabilities in smart contracts and protocols. In addition to human whitehat hackers, our AI Agents function as Red and Blue teams, actively engaging in simulated attacks to stress-test protocols and identify potential weaknesses. This comprehensive approach allows developers to proactively identify and address security issues, ultimately enhancing the robustness and resilience of their projects. 🕷️ Bug Bounties: Our Bug Bounty listing platform provides developers with the opportunity to list their protocols and offer bounties to white hat hackers for identifying vulnerabilities. By aggregating millions of bounties from various platforms and utilizing AI tools, we streamline the testing process, reducing up to 80% of the workload typically associated with security testing. This allows developers to efficiently identify and address potential vulnerabilities in their protocols, ultimately enhancing the overall security and resilience of their projects. 🪙 And lot more token analytics features for regular users, this will give you the opportunity to explore our Dapp for yourself and have some fun diving into the security platform of the future! I’m sure you’re excited to try it all out yourself, which is why we have some exciting news to bring to the #Guardians of the blockchain! But just before you continue the read and see the beans have been spilled, we have to take this opportunity to share with you that this large step to becoming a security leader is but only 20% of what we have revealed. This will be at the core of what Aegis stands for and hopes to achieve. The focus here is upon our Dapp, and in time we will slowly bring forward information/updates regarding segments of what makes Aegis a force to be reckoned with. Now that you’re fired up and excited to all of the announcements to come, let’s get to the news you’ve been waiting for! 🎉 We’re spilling the good news, and are happy to say we are now set for public release! The team at Aegis are overwhelmed with the development, support from teams, community, partners and more on what we believe to be an institutional-grade product. But the fun doesn’t stop there, this marks the start of what we aim to become, as it will take time and cycles to become better and better. Constant advancements will be set in place to attain the goal of achieving blockchain security. A statement from our CEO- Brian Hunt: “I can confirm from the security conferences I attended with Centralized security firms Peckshield, Hacken, Certik, BlockSec presentations, they are trying to achieve something similar and it will take them years. Decentralized AI for Security!” This initial drop of our dapp will be to get users signed up to gain access, in which we’ll whitelist users to get the ball rolling. 📣 To end this segment, let’s get the party started with the long awaited Aegis Ai Security Dapp and sign up now!

AEGIS AI

127,936 views • 2 years ago

While Rahul Gandhi makes an emotional appeal to the central government asking them to stop the destruction of environment in Andaman & Nicobar, the Congress government in Telangana is doing just the same! Kasu Brahmananda Reddy park / KBR park is an urban forest spread across 390 kilometres in the heart of the city. KBR has been home for over 600 species of plant life, 140 species of birds and 30 different varieties of butterflies and reptiles. You see peacocks all over the park, many snakes too are spotted regularly. Animals like pangolin, small Indian civet, peacock, jungle cat and porcupines live there. People are allowed only for limited hours in the morning and in the evening & that too only in a small section of the park to protect the environment. At any point of time, when you pass by KBR, you can clearly feel 2-5 degrees temperature drop. In the heart of the city’s Jubilee Hills, it is a beautiful green lung space. KBR Park was declared an Eco sensitive zone on 27 October 2020. Traffic around KBR has been an issue. There was a proposal to build flyovers at KBR to ease the traffic by the urban planning authorities. People protested and the then CM KCR instructed everyone to stand down on the project since it destroys an ecosystem. Today! Revanth Reddy as part of the Strategic Road Development Programme and H-CITI plan is going ahead and constructing 6 flyovers and 6 underpasses. All because he wants to make area around KBR park - “signal free”! Budget is Rs 1,090 crores. No of trees that will be destroyed? 1942 mature trees will be uprooted!!! There is no environmental clearance to the project. Congress Government came up with an intelligent way to bypass this. They split the project into 6 separate projects and now they don’t need any clearances. What’s worse- the Telangana High Court had given a stay order & to bypass that, the shameless government is carrying out demolitions in the dead of the night. They want to finish the destruction before the courts open again! Bulldozers come in the night and work nonstop to create a chance to fatten the purses of contractors. These flyovers and underpasses will destroy the ecosystem completely. But yeah, who cares? Since it is Congress that is destroying the lung space and since it is not Andaman & Nicobar island, since it is Telangana and most importantly people in Hyderabad don’t need OXYGEN, this destruction is absolutely 💯 percent okay 👏🏼👏🏼👏🏼 Video from last night

Revathi

32,003 views • 2 months ago

🚨Danielle Smith FIGHTS for all Canadian exports in Washington, D.C. Premier Danielle Smith fights for all Canadian exports—not just oil and gas. What a difference from the selfish, destructive approach by Justin Trudeau—and other premiers. Ezra Levant 🍁🚛 is in Washington, D.C., where he just met with Premier Danielle Smith for an exclusive interview. She’s here making a full-court press, trying to convince the incoming Trump administration to call off their proposed tariffs on Canadian exports. By the way, she’s fighting for all Canadian exports—not just oil and gas. She’s fighting for Ontario’s auto makers and B.C. miners, too. What a difference from the selfish, destructive approach by Justin Trudeau—and other provincial premiers, by the way. In a shocking proposal, Trudeau suggested that Alberta’s oil patch be made the sacrifice community and that Trudeau should shut down Alberta oil exports to the U.S. What a weird, self-destructive response to Trump. Trudeau really is an awful negotiator. None of this would be necessary, if he had stopped allowing hard drugs and illegal migrants to cross our border into the U.S. Trudeau literally prefers a trade war to fixing our borders. He wants this fight. And he wants Alberta to pay the price. It’s unthinkable that Trudeau would threaten any other Canadian industry this way. But like his father Pierre Trudeau, who brought in the National Energy Program, Justin Trudeau has always hated Alberta and the oil industry. In his final, pitiful weeks as prime minister, Trudeau is using Trump as an excuse to take one last run at Alberta. By the way, at Rebel News, we’re fighting back. We’ve launched a campaign called “Hands Off Alberta”. Just yesterday we debuted our beautiful billboard truck with that message, driving around Ottawa, collecting petition signatures at More news to come tomorrow — we’ll find out what Trump does, and what Canada’s response will be, and what Premier Smith will do.

Rebel News

96,437 views • 1 year ago

Been up almost the entire night making big audio gainz on the SH4 CPU for the Sega Dreamcast port of Mario Kart 64! It took about 3 of us pitching ideas and optimizing together, but holy shit, the 200Mhz SH4 is keeping up 99% of the time doing all synthesis and mixing in SW! What you're seeing is the first hardware capture of Mario Kart 64 running on the Sega Dreamcast with working audio playback... and trust me, it was not easy to get here! First of all, all of the audio signal processing for synthesizing individual notes from sampling instruments then mixing the SFX channels and the BGM together into a single audio stream is being done completely in SW on the DC's 200Mhz SH4 CPU--while it was done in HW on the N64. It is also carrying the whole T&L load for rendering with extra overhead per draw call due to us using our OpenGL 1.1 driver for graphics (GLdc). You can currently see a teeny little bit of slowdown at the beginning of the race when all 8 karts are bunched together, emitting their own SFX, which all has to get mixed in SW, bogging down the CPU... but don't worry, plenty of gainz left! On the left is a very interesting routine which proved to be incredibly gainzy when accelerated... So lets jump into what we did to this "aResampleImpl()" routine! 1) Compiler Optimizations: Everything is compiled with -Os by default to save RAM, because jnmartin is preloading almost everything up-front; however, we've created a "hot file" listing within the Makefile which allows us to build specific perf-critical translation units at with the -O3 optimization flag. 2) Manually managing the data cache: notice how many prefetches and barriers are in this routine in order to phenangle GCC's codegen to be somewhat similar to the ordering we've done things in C. Additionally, I've gone through hell in Compiler Explorer to ensure that all of the buffers used here can be prefetched in a timely manner, so that they're cache-resident before they're actually used. 3) SIMD: While we were discussing this routine in Discord, Paul noticed that the sample calculation was essentially performing a dot product of 2 4D vectors... which... GUESS WHAT. The SH4's FPU can do with a single instruction, FTRV, which is what "shz_dot8f()" provides an intrinsic around... The gainz were pretty substantial, despite having to convert back and forth between int16_t and floats. The new FP SIMD code can be enabled with "SH4_SIMD_GAINZ," otherwise the slow integer path is taken, so you can see the code difference. 4) Custom memcpy() routines: The builtin memcpy() routine that we're given in GCC15 from Newlib for the SuperH architecture is EXTREMELY slow... about as slow as copying byte-by-byte in ASM, so doing any sort of multi-byte loads and stores (provided adequately aligned buffers), even in C code, offers substantial gainz. Anyway, that's it for today! Stay tuned for more gainz!

Falco Girgis

15,547 views • 1 year ago

Google just confirmed the first case of hackers using AI to build a zero-day exploit from scratch. An actual zero-day vulnerability that no human had EVER found before, discovered by an AI model, turned into a working weapon, and aimed at a mass exploitation campaign targeting thousands of systems simultaneously. Google's Threat Intelligence Group caught it yesterday and killed the operation before it scaled. But the details of how it worked are genuinely scary: The AI found a flaw in a popular two-factor authentication system that traditional security tools had missed entirely. The vulnerability was a logic error buried deep in the authentication flow where a developer had hard-coded a trust exception years ago. No human security researcher or automated scanner had caught it. The flaw was invisible to EVERY tool the cybersecurity industry has built over the past two decades. But the AI spotted it immediately. Then it wrote a full Python exploit script to weaponize it. Google's analysts could tell the code was AI-generated because it had textbook formatting, educational comments explaining every function, and even a hallucinated severity score that doesn't exist in any real database. The AI literally graded its own attack with a fake rating. So the code had MISTAKES in it. The criminals' implementation was clumsy enough that it probably interfered with the actual deployment. This was the sloppy first attempt by people who are still learning how to use these tools. And it still found a vulnerability that the entire cybersecurity industry missed. Google's chief threat analyst John Hultquist said: "There's a misconception that the AI vulnerability race is imminent. The reality is that it's already begun. For every zero-day we can trace back to AI, there are probably many more out there." But here's where it gets truly insane... This wasn't even a sophisticated operation. North Korea's APT45 hacking unit is sending thousands of repetitive prompts to AI models, recursively analyzing known vulnerabilities and building an entire exploit arsenal that would be physically impossible for human hackers to assemble at the same speed. They're essentially industrializing cyberattacks. A Chinese state-linked group jailbroke Google's own Gemini by simply asking it to "pretend to be a network security expert" and then used that persona to research how to hack TP-Link routers and corporate file transfer systems. Another Chinese group deployed autonomous AI agents that probed a Japanese tech firm with minimal human oversight, deciding on their own which tools to use and pivoting between targets based on internal reasoning. And then there's PROMPTSPY, an Android backdoor that calls Google's Gemini API to read your phone screen in real time, navigate your interface autonomously, capture your biometric data, replay your lock screen PIN, and block you from uninstalling it by placing an invisible overlay over the uninstall button. It literally OPERATES your phone using commercial AI tools anyone can access. Everyone spent the last 3 years arguing about whether AI would take people's jobs. Meanwhile AI is making every password, every firewall, and every two-factor authentication system on Earth fundamentally less secure. The entire $190 billion cybersecurity industry was built on one assumption: that finding vulnerabilities is hard and requires deep expertise. But AI just removed that assumption from the equation. And the scariest part is that Google said the criminals made errors this time. The implementation was rough and the campaign probably didn't fully work. These were amateurs, now imagine what professionals are able to do. There's a reason Sam Altman predicted an inevitable massive cyberattack THIS year. What do you think?

Ricardo

50,564 views • 2 months ago

English is literally the hottest programming language. It's absolutely crazy that you can build a complete product in plain English. I'm using Rocket in this video. This is a new app. You type what you want, and Rocket builds it for you. This is great if you want to build: • A landing page • A complete web application • A mobile app • A dashboard to showcase something • An internal tool to automate anything This is another example of how developers should become comfortable being copilots for AI agents (instead of using AI as a copilot). Some of the things I like about Rocket: 1. One-click deploy to Netlify (I use Netlify for all my projects) 2. GitHub integration 3. Supabase integration for your backend 4. Built-in support for Stripe 5. Built-in support for Resend 6. Google Analytics integration 7. Smart AI search with Perplexity 8. You can also integrate with GPT models, Gemini, and Claude 9. You can make visual edits by describing what you want 10. You can upload images and have Rocket implement them Best of all are the templates: They have a large library of templates that will help you get started. These templates will help you save money (because of fewer tokens), and you can modify them as you see fit. I read on the site that you can also bring a Figma file and turn it into an app, but I didn't test that feature. By the way, you can start using it for free. Here is the link: Thanks to the Rocket team for their support and for collaborating with me on this post.

Santiago

30,944 views • 1 year ago

Anthropic CEO Dario Amodei just revealed the hidden bottleneck that will kill most AI companies in the next 18 months (Save this). The insight comes from a principle in computer science called Amdahl's Law. Dario's argument is simple when something starts working really well inside an organization, you have to immediately ask what isn't working well around it. Amdahl's Law states that the maximum speedup of any system is capped by the fraction you haven't improved and that applies to companies just as brutally as it applies to processors. If you can suddenly write three or four times as many pull requests as before, you don't get three or four times the output but you rather get a pile of code no one can review, verify, or trust. The data makes this impossible to ignore. Teams with heavy AI coding adoption are merging 98% more pull requests but PR review time has ballooned 91%, deployment velocity is effectively flat and 96% of developers don't fully trust AI-generated code reaching production. AI generated code produces 1.7x more issues per pull request than human written code, 0.83 issues per PR versus 6.45. Veracode's 2026 State of Software Security report found that 82% of organizations now carry security debt, up 11% year over year, with critical security debt surging 36% in a single year driven directly by AI-generated code reaching production faster than security teams can handle. What Dario is describing is a systems problem, not a software problem and coding is roughly 20% of the software delivery cycle. Even at infinite coding speed, you're still bottlenecked by review, security, verification, testing, and deployment which make up the other 80%. The enterprises that win are the ones that identify which part of their system is the new constraint after AI accelerates the old one and fix that next. This is why Anthropic's Claude Code focuses on the full development loop, not just generation, and why the verification and security layer of the AI stack is where the next wave of enterprise value gets created. This is also why Anthropic as a company is positioned differently than most people realize. Anthropic's 2026 Agentic Coding Trends Report found that organizations using full-loop agentic coding workflows where AI handles not just generation but testing, review, and deployment validation reduced their software defect rates by 43% while increasing velocity by 2.8x. Claude Code now authors 4% of all GitHub commits and is on track to hit 20%+ by year-end, with the full-loop use case growing 3x faster than pure code generation. Dario has been building Anthropic around the exact insight he's describing publicly ,the constraint isn't writing code but rather everything that has to happen after.

Milk Road AI

52,190 views • 2 months ago